Octopus Shield OCTOPUSSHIELD

Brand impersonation intelligence

See the fake site before your customers do.

Octopus Shield watches public certificate signals and suspicious domain activity to surface brand impersonation early — with source, time and evidence attached to every finding.

Candidate review Demo / synthetic
Illustrative data. Not a customer, not a live finding.
DomainFirst seen (UTC)SignalsScore
northbay-login.top19 Aug 2026 14:32 homograph · new domain 91
n0rthbay.com19 Aug 2026 14:31 leetspeak · short TTL 88
northbay-secure.info19 Aug 2026 14:31 keyword append 74
northbay.com.verify.top19 Aug 2026 14:30 subdomain masking 69

Why this is flagged

  • Character substitution against a monitored brand string
  • First certificate observed minutes ago
  • No prior certificate history for this name
  • Public suffix and registrable domain do not match the brand
9Active Certificate Transparency logsmeasured 19 August 2026
284 / 284Automated checks passedas of 19 August 2026
0Runtime application dependenciesby design
1,174Certificates read in one measured 30-second local runsingle run on 19 August 2026 — not a sustained rate

How it works

From certificate signal to evidence.

Every finding travels the same path, and every step leaves something you can inspect afterwards.

  1. Discover

    Certificate Transparency logs, crt.sh and Censys are read continuously. The log set refreshes itself, so a frozen or retired log does not silently stop collection.

  2. Normalize

    Names are folded to a comparable form: homograph characters, leetspeak substitutions, punycode and internationalized domains are resolved before anything is compared.

  3. Score

    Each candidate receives a pre-score from string distance, substitution patterns, keyword placement and certificate newness. The contributing signals stay attached to the record.

  4. Observe

    Optional, off by default. If enabled, a copied page can report an anonymous, unverified observation — including whether the visitor looked automated or human. No identity is involved.

  5. Evidence

    Source, timestamp, certificate reference and the signals behind the score are kept together, so a finding can be reviewed, disputed or handed to a registrar.

Three things you get to know.

What appeared.

Newly observed domains and certificates tied to the names you monitor, each with the source that produced it and the time it was first seen.

Why it matters.

The signals behind each candidate are written out — character substitution, keyword append, subdomain masking, certificate newness — so a person can judge it.

What you can prove.

Findings carry their source, timestamp and raw certificate reference, so a takedown request is not built on a screenshot.

Operational console

The same discipline inside the product.

The console shows what the system currently holds. When a number is zero, it stays zero — no placeholder rows, no invented activity.

Open the console

Sentinel

When your page is copied, the copy can say so.

Sentinel is a small script you place on your own site. If the page is copied and republished under another domain, it shows the visitor a notice and points them back to your real address. It runs before any network call, so the notice appears even if the request never completes.

  • No identity is collected — no email, no username, no account identifier.
  • The optional observation channel is anonymous and unverified by design.
  • It does not block, redirect silently, or make an enforcement decision.

See the synthetic illustration

Our commitment

Security without invented certainty.

  • We do not say blocked when we only observed.The product surfaces and documents. It does not block traffic, and it does not claim to.
  • We do not show 100% coverage when coverage has not been measured.Coverage is not currently measured, so we do not publish a coverage figure.
  • We do not turn anonymous observations into identity decisions.Observations are anonymous and classed as unverified. They never become a verdict about a person.
  • Every operational number has a date.A figure without a timestamp is not evidence, so we do not present one.

Evidence & validation

Evidence you can inspect.

Internal AI Security Validation — 2026
Navy — landscape · OS-AIV-2026-0001

Internal AI Security Validation — 2026

Self-issued engineering validation attestation.

This is an internal validation attestation issued by Octopus Shield / Çelebi Bilişim Ltd. It is not an accredited third-party certification.
Reference
OS-AIV-2026-0001
Year
2026
Type
Internal validation attestation
Accreditation
Not accredited
Issuer
Octopus Shield Engineering / Çelebi Bilişim Ltd.
View validation record

References

References available on request.

References available on request.

No approved public references are listed at the moment. Internal and test properties are not customers and are never presented as such.

DEMO COMPANIES 112 institutions · 84 countries · 6 continents Demo companies →
  • 瑞湖银行CN
  • 长风证券CN
  • 明州信托CN
  • 云岭商业银行CN
  • Северный Кредит БанкRU
  • Банк «Ладога-Инвест»RU
  • Банк «Дніпро-Степ»UA
  • Банка Моравска УнијаRS
  • Harmattan Trust BankNG
  • Ashanti Delta BankGH
  • Benki ya Ziwa KuuKE
  • Benki ya Serengeti MasharikiTZ
  • Cascadia Union BankUS
  • Beacon Harbor FinancialUS
  • Sierra Vista TrustUS
  • Granite Ledger BankUS
  • Banco Serra DouradaBR
  • Financeira Amazônia VerdeBR
  • Banco Pampa UniãoBR
  • Banco del Plata AustralAR
  • Coral Sea Mutual BankAU
  • Outback Pastoral BankAU
  • Southern Cross SavingsAU
  • Aoraki Community BankNZ

These 112 institutions are invented. None of them is a customer, a partner, or a real organisation. They are shown only to illustrate how the product looks once brands are being monitored. Names are written in their original scripts because impersonation detection works across scripts.

See what is already out there under your name.

A demo runs against real public certificate signals for the names you choose. Nothing is published, and nothing is sent to your customers.

Request a Demo

As of 19 August 2026